URLhaus Database

You are currently viewing the URLhaus database entry for https://wordpressdes.vanzolini-gte.org.br/fundacaotelefonica.org.br/2XpWEGDlt9CAwIzegFiGW8QMtd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1917914
URL: https://wordpressdes.vanzolini-gte.org.br/fundacaotelefonica.org.br/2XpWEGDlt9CAwIzegFiGW8QMtd/
URL Status:Offline
Host: wordpressdes.vanzolini-gte.org.br
Date added:2021-12-24 18:18:11 UTC
Last online:2022-01-20 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-24 18:20:49 UTC to abuse[dot]br{at}telefonica[dot]com,abuse[dot]tgsolutions{at}telefonica[dot]com)
Takedown time:26 days, 6 hours, 23 minutes Bad (down since 2022-01-20 00:44:41 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-2575601481636491O.xlsxls ad703c5d173ecc9110d797f3272128d0bd21745acd34d207171021b8f448c5b3Virustotal results 31.67%Heodo
2021-12-25T08697055831159890095N.xlsxls c969d1228ff7ade37decc83d278373e6d1192daa2d311a14492e8853c093475bn/a SilentBuilder
2021-12-25Q68243404R.xlsxls 51e620f9f90223bc5d219c2f597f0f52a7f5f512a7bc961ceee43a4656368baen/a SilentBuilder
2021-12-25533962665542833568B.xlsxls 20cce1bf56b3a2720d94e8d9b18492afb7e79fbe22ede91ed391db9b3640ab76n/a Heodo
2021-12-25312356557072666.xlsxls 7b81a2a5b95e764d22b91ed49615ff4324161f6dec19ce655eac3e1f2dd626fen/a Heodo
2021-12-25T0495529601.xlsxls 35b8bd6b780b6d943d1f3a6a02a77d24090358793731cfb8f86fdfc880d77010n/a Heodo
2021-12-255330087957474254147.xlsxls dd9aeb4e572685c0730d665190460d3f314a19558f77c77687d47204b5966c1bn/a Heodo
2021-12-25B690602289602.xlsxls 9d1ea6eb483f1b8c5d8282bc88904d9b9426bf1d25ce82234df3ceeb15a41f54n/a Heodo
2021-12-253254224121291297R.xlsxls db5ad311da7cbf421ecff37ab3585f6d5e6123bc831d10a5df175b9a7ba7e484n/a Heodo
2021-12-25U02517380693457199628E.xlsxls bd47d239b29d4672ce03908c935d65dd98b77db7c23343a2c2f670eab11e246dn/a Heodo
2021-12-25Q93938337B.xlsxls 8b2064c83ef2072bff59d157b7f91ec7c495104914b59a7a198fa5f4a68ce1b4Virustotal results 31.67% Heodo
2021-12-254146314399072501C.xlsxls 9cea5bd5d462f121565c0abcae5d934535589dd72a023924c487e7d3b46b1376n/a Heodo
2021-12-25D822383628S.xlsxls afe9cf92e6e3688bc09dddad0da3b393a87bdfc99955468b48a6692d9bac1342n/a Heodo
2021-12-25Y59799495340364043L.xlsxls 5df0d62dbf36dca8b981369697f63ccbe3848eee701ba22b2dc4eb449eda31a4n/a Heodo
2021-12-2530491570L.xlsxls 04fe122c0472520213cfaa008aa6cb7b33c95cfd5e43a0860f57b7ddb49145b8n/a Heodo
2021-12-25O427551919324833602569.xlsxls c45ebc2f0a1e592d11d3db45a8b42c58385daa5c0fd1ef07ea7f98c82d269006n/a Heodo
2021-12-253377164U.xlsxls 2f9d9c4e20d1c6eeeaf710cbf292bd745edb018e2ccb684dd81ce4f9e8779d97n/a Heodo
2021-12-25K9766123580372688P.xlsxls 0eaddc4efc5618c94807a22776929449fb6615461408889af47602c9d52d3feen/a Heodo
2021-12-25E8467272270923B.xlsxls aba3b9156a0ae01f974a2504cea46b31e23f6734f523123465281a85195d8081n/a Heodo
2021-12-25L86811231R.xlsxls 37029ffaf8784e69ca60e4f34de09623001928c7a7c24e74abe50d5c173da19cn/aSilentBuilder
2021-12-2575552926R.xlsxls 5f8a6b7049df4182bacef894f204054ddd268ade96b098bdf9f4e5545b861182n/a SilentBuilder
2021-12-25N4408762905471308C.xlsxls cd7405cf2ff6fee4e17a155d5ac12ce05f8eb0d299862c99d57e32e569ec8562n/a Heodo
2021-12-25X35184286Q.xlsxls 978a5693d26206af73d37fe9c4ed60c4b45462afa41057e18dbe3525830f6864n/a Heodo
2021-12-25542133774433989585P.xlsxls 77aa74d92c1314ffb5a41afe0bcd68c49e8d5389c3db99a12ab59bca64797539n/a SilentBuilder
2021-12-25P15948277351E.xlsxls 6082f08619d3cb26ff92b4c9c257cce407f4c266c856c28716050be8dc6e7befn/a Heodo
2021-12-25H27418252117K.xlsxls da7cad8765848a1a6e8428cc1f47db30624ad64eef92fb4096d7445df78fe4d0n/a Heodo
2021-12-25L013683538085625154H.xlsxls ea1207c9664e6ca00daa59bf6a5c89695ec093a1fb74929acc4b2391169fd07dn/a Heodo
2021-12-259642300907220234.xlsxls ed1c76dc252e5796effc932b9c751518080d610c35f431f5e72b285bae07abc6n/a Heodo
2021-12-257735415995842A.xlsxls 60c0cb213c196027985ad7655f12ffbebb5ec878816364a7c60e5afd10e2a335n/a Heodo
2021-12-25R9635812580214724P.xlsxls 2c7696066247b11e35ae0972e00723cae55766466f6639c01e83c482b82899e3n/a Heodo
2021-12-25F05518447572845478.xlsxls 56f256ebed180da8fefccf1b94718a2a384b267071183c8ae71723dd6920ec28n/a Heodo
2021-12-256565239757478526521.xlsxls 13150b38b2a08b416fa6691a92edd46170a4d6df0c6bcf3538b2c5a0fb345355n/a Heodo
2021-12-255881183027880593284.xlsxls 2f6f269b058dbb4692154e05bd19c1af1255f94e87989ee4fcb270b04bb8d1a0n/a SilentBuilder
2021-12-2548953484.xlsxls 44d70fe529afd5c0ff1141380c9457fe94a4e70123214cb75a6a91565e492de4n/a Heodo
2021-12-25Q266253102011694H.xlsxls b5bd0a110e06bbc2d82d4b72c8bca7369c361cb8e07e325637784bd8bac02129n/a Heodo
2021-12-25451106319121294800844L.xlsxls c9b5d2eae56caa3e24de04e34c061dca4d50fbf57262cad5f18c5eae62be7cbaVirustotal results 32.76% Heodo
2021-12-2543991371038530518927.xlsxls 74e40a9df26f90539dc407121e476089bf1dd4456b9444d5f6a5cd97a446aa12n/a Heodo
2021-12-2547670864772505A.xlsxls 19d8e9a6473fa372ab9095906f87f2957e8871b67bdf15d7088750fc3fee4244n/a Heodo
2021-12-25800395506472838770D.xlsxls f28e9066b8fd7d3c09d49d4848cdf82c7e60a1bbb8fe1fc644118b89e057f8edn/a Heodo
2021-12-252329873338573.xlsxls 24bf2f70bdc759d99cb9fda0d2c80bec7e0cedb6159312435d7cc8dbef7c3950n/a Heodo
2021-12-25Q7899864E.xlsxls efe55ba04b3e3a91494af25c97a3dca0408ddf023372eb3e438343546acd210dn/a Heodo
2021-12-253777798288630757F.xlsxls 150e285485d82e096dcd7bc791179fed090448bf3453b5ac71c8c70d3a7be1b0n/a Heodo
2021-12-25X261753008673891U.xlsxls 82d9adb557fa314e3101740c3509c722daa1be5ac6a476580dc3a6bbede5e33dn/a SilentBuilder
2021-12-2572603334840527X.xlsxls 2dea6b2c64e11de4e2dbbc73e0d56e5fbcd0605caa2c1a5ed94a658486dceaben/a Heodo
2021-12-2546937576R.xlsxls 1847ca4ba74839a10ecdf34225ac61d6c8ae7bc09bde5c637582ece96e28ce78n/a Heodo
2021-12-25F334321291935567.xlsxls 1c06556afa430a804d882e948d33d6bb5fae35792cff58ecb1646480e81e1d12n/a SilentBuilder
2021-12-2576627594819R.xlsxls c3ddc390201f2ca1208a5c56397185466e916dd6d2b92dc174dc2fad5a613bd5n/a Heodo
2021-12-2539214918405928287473.xlsxls d7a318a0dc8e111a79ba80f8af607849c3fe7158b0627d0539bde12d190a9460n/a SilentBuilder
2021-12-25X6162147.xlsxls 2f9dc9c44ec5c248067843135aa0d8d49099d6578d645f64d3489ed873b65cf4n/aHeodo
2021-12-25506075199.xlsxls b8403fab8e756e881a14bd25996508d692cf13748493e4669d2ae94be6aae320n/a Heodo
2021-12-25I3068234P.xlsxls 5ce76700d99f90cce5fbc2ccbadf816fd224a5ad47fe551dbf75bb73c892b493Virustotal results 20.00% Heodo
2021-12-25H35871789804961.xlsxls 1cea43d27d3613e0ac830fdf92e634b4495d4cd276ea6f5a3a925ebf41ec3a8fn/a Heodo
2021-12-24044833280119631O.xlsxls 171ab065c531efdd511197d6683a686875a71f88e18a0690903ee06f3d250e6en/a Heodo
2021-12-24276197361562.xlsxls d4eea02e8c23c88e3966b019cc00eb0639baa3f167b3b3ec85888bfd29416fa0n/a Heodo
2021-12-243857016M.xlsxls 0dcfe02323f3c194e4dc38116bcd31eaf1eb7760a701d38d683137481c625864n/a Heodo
2021-12-242482689676399217S.xlsxls bc82a370a985332a3cd9d6b7e1f6b2da28e63e4b6c0900550ecd1947cc36cac2n/a Heodo
2021-12-24S51919950169321432280P.xlsxls 9318a3ea4947804ca30f39787e1fa8141d8cf5b786f45d0c9c4fb7844178b0b9Virustotal results 20.00% Heodo
2021-12-24I0574651259464J.xlsxls 5768d14cf5cd3e8f9e681af2aa83602fef731252e4b7227008085c96b87ee5cfn/a Heodo
2021-12-24D4361304357C.xlsxls eddcad26fe5b98aaf5f8a319cdfb04cccedbf9bf3ffe59d7097b879b7028797fn/a Heodo
2021-12-246445524.xlsxls 39040f1d6d0f2c4d3577b8f353543e975cead7314c16a891ec321fa125c166f2n/a Heodo
2021-12-24R238698261291533.xlsxls ebad32d3393974502f894cc2ba95df6e40afed688bba9cf9c40a24adb8dce19an/a Heodo
2021-12-243856510449513260673F.xlsxls 6420663d3cc6caf082a00566ba0de8988416745c7682a6ffd2da790e42aedc4bn/a Heodo
2021-12-24935634634318376T.xlsxls ab5ba308cadc99cb02dd8df1e6572205bec3b7cfd6409a2842ed28cf8ef8166an/a Heodo
2021-12-24G964435861075A.xlsxls 604d2f879cc62d012acbbe503193160ef7779c1ded5e5f3dedca0d7caea382a3n/a Heodo
2021-12-244001529.xlsxls 84521d34b9bfb5fa47786ee8e155c505a6de3c04ac8356dc2061265acc9274aen/a Heodo
2021-12-24I5316510650988443358Y.xlsxls 07ec145282df7082b4d810764bce7045dd6be78f70df3a112fdf8325cef7ccean/a SilentBuilder
2021-12-24804087594771912280.xlsxls 1c77d062fb0a4e11f930e775a722ddcb8734f6c4d5c65e4a7c09da9d1a311e7fn/a Heodo
2021-12-24545939607066893690O.xlsxls ff3c37f2ba563f21df4c775a7c5045fb1cb936ab4904d6e4f7f8d674e0631427n/a Heodo
2021-12-24T99628842440300436T.xlsxls 3ba6ac05affb898c254623d031a5a0f1e2f4f0fb41547c322f82ba0198452dd1n/a Heodo
2021-12-24F588970375783245180082.xlsxls c812d15a947a9d9fe9b5d7543bed5be91710545cd7498fa91dcea5069bcd360bn/a Heodo
2021-12-24H815213128363323468E.xlsxls 48cffc79c3944f7bc0afbd85ea10a2c37cc16d5794f021cf539b19618c746c85n/a Heodo
2021-12-2480733271.xlsxls 76f683a31126eb28ca638470852ff61540f14bfb64aa0b96e988b33135914e71Virustotal results 15.79% SilentBuilder